![]() |
#1 |
Junior Member
Join Date: Apr 2007
Posts: 12
|
Security breach
First of all: great product.
Now that's out of the way please allow me to tear you a new one. Your "faq" and email states that the attack was blocked. It clearly was not. If it was blocked I would not be waking up to your email. It would have been even better if you had not locked the FAQ thread so I (and no doubt others) wouldn't be about to create 1000 threads with the same content. I am extremely dissatisfied that my personal information has been left vulnerable because of your lax security. I bet I am not the only one. |
![]() |
![]() |
![]() |
#2 |
Junior Member
Join Date: May 2008
Posts: 2
|
Agreed, blocked is not the same as "they have your email". Also the passwords, where they just MD5 hashes or where they salted?
|
![]() |
![]() |
![]() |
#3 |
Guest
Posts: n/a
|
Please delete my account.
It's not open to discussion. Thanks. |
![]() |
![]() |
#4 |
Junior Member
Join Date: Sep 2006
Posts: 15
|
Yeah we need to know more about the password leak, you try to play it down in your FAQ but you recommend changing it on other forums, tell us more.
|
![]() |
![]() |
![]() |
#5 | |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
wow ... drama llama's are in season
Quote:
The FAQ is quite clear ... breach detected and stopped ... RECOMMEND you change your password (covering their arses) ... Also, if you're a brain dead retard and use the same password on other sites, best you change that password as well I can't see what more could be said "If you don't like DNAS, write your own damn system" So I did |
|
![]() |
![]() |
![]() |
#6 |
Guest
Posts: n/a
|
I've not used this forum in years and luckily the password was one I no longer use.
However the email I received said "your email address was exposed as a result of the attack", if it was just my email address why tell me to change my password? Was it more than just email addresses that were exposed? Is it a hash that someone has their hands on or is it more than you're letting on? |
![]() |
![]() |
#7 | |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
Quote:
I for one respect the fact that I was contacted about this - if they were sure passwords were not compromised, they could've remained silent about it and nobody would know any different - may get some more spam, but my wife wants my dick bigger and stay hard longer, so it's win win ![]() "If you don't like DNAS, write your own damn system" So I did |
|
![]() |
![]() |
![]() |
#8 |
Guest
Posts: n/a
|
Oh don't get me wrong, disclosure is good and I'm glad they've come forward.
My email address is already all over the Internet so I'm not too upset, I would just like absolute confirmation that nothing else was breached. |
![]() |
![]() |
#9 |
Junior Member
|
So were passwords stored in the DB as plain text?
|
![]() |
![]() |
![]() |
#10 |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
I think all the info they're prepared to release was in the email
"If you don't like DNAS, write your own damn system" So I did |
![]() |
![]() |
![]() |
#11 |
Junior Member
|
Ok so they blocked an attack on the DB, entirely or only in part? How long did the attackers get access to the DB before they were blocked. If they did get access to the DB then surely more than just email address obtained.
|
![]() |
![]() |
![]() |
#12 | |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
Quote:
change any passwords that are identical on other sites move on with your life how hard is that? "If you don't like DNAS, write your own damn system" So I did |
|
![]() |
![]() |
![]() |
#13 |
Guest
Posts: n/a
|
The fact is the email addresses were stolen.. I don't care about this stupid Winamp account password, but I do care about my private email and spam!
I want my account deleted as well (havent used it since 2003 anyway.) Please delete it or let me know how to. Cant find the option anywere, not even in the help section. |
![]() |
![]() |
#14 |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
did you read the FAQ link posted in the email?
"If you don't like DNAS, write your own damn system" So I did |
![]() |
![]() |
![]() |
#15 |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
here ... let me read it for you
5) How can I delete my account? We understand how important trust is on the web, and some of you may wish to delete your Winamp Forums account. To delete your account make sure that you are logged into the Winamp Forums and follow these simple instructions: Scroll down to the bottom of the forum home page and click on View Forum Leaders. Scroll down to the Root section to see the list of Administrators. Send your deletion request to DJ Egg or DrO using the contact link to the right of the administrator's name. The Administrator will delete your account upon receiving the private request message and send you a confirmation email once the account is deleted. "If you don't like DNAS, write your own damn system" So I did |
![]() |
![]() |
![]() |
#16 |
Junior Member
|
|
![]() |
![]() |
![]() |
#17 |
Join Date: Sep 2003
Posts: 27,873
|
will everyone keep it in check please, especially telling people to STFU is not helpful.
as for the questions raised, i'm not going to answer them as i do not know the complete answer and so do not want to spread mis-information. as such what is officially provided is all there is to know on the matter though there may be further clarification (but i do not know and cannot confirm about that). -daz |
![]() |
![]() |
![]() |
#18 |
Junior Member
Join Date: Apr 2007
Posts: 12
|
The only reasonable thing you have posted in this thread jarorama is everything from "my wife wants" in post #7.
You're not site admin, let them tell me what the breach was, what was taken (I understand databases and SQL injection so I sincerely doubt all they did was code: edit: sorry mod, you posted while I was constructing this post. |
![]() |
![]() |
![]() |
#19 | |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
Quote:
no need to get your panties in a bunch, sweetheart "If you don't like DNAS, write your own damn system" So I did |
|
![]() |
![]() |
![]() |
#20 | |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
Quote:
I've admined fora over the years, and know what will and wont be disclosed by 99 out of a 100 admins in such circumstances but, right now, I'll let the drama llama's carry on their whinging and whining "If you don't like DNAS, write your own damn system" So I did Last edited by jaromanda; 16th February 2011 at 13:07. |
|
![]() |
![]() |
![]() |
#21 | |
Junior Member
|
Quote:
If there was any amount of access to the DB, it is not unreasonable to assume it was more than just emails that were stolen. |
|
![]() |
![]() |
![]() |
#22 | ||
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
Quote:
I'll stop if I'm told I'm doing anything wrong by admins ... not by someone who made two posts 4 years ago and hasn't been back since thanks for your input, though, sweetheart Quote:
interesting observation ... the biggest DOOMSAYERS have less than 5 posts on the forum before today just saying is all "If you don't like DNAS, write your own damn system" So I did |
||
![]() |
![]() |
![]() |
#23 |
Major Dude
Join Date: Jun 2008
Posts: 1,665
|
Thanks to the admins at being honest here. Okay, that is a legal requirement when you get your database stolen, but how many other forums get quietly hacked and then everything covered up in secrecy?
Can I make a small suggestion? Any chance of making the "Contact an Admin" links a little easier to find? When I dropped by this website on Jan 8th at 20:47 hrs GMT NOD32 blocked a connection to ciriso9********/multi/jnaojtgpizin.jar (Don't be stupid enough to follow that link, I am typing it here purely as an example...) If I could have found a way to easily contact an Admin, I would have reported this. Trouble is, it was not clear how to report anything so instead of wading around an infected website I ran away. ![]() Oh - and nice to see NOD32 in action. Often sit in all kinds of silly debates about the qualities of different AV products, and it is always fun to see NOD32 getting the gloves off. Edit:Oooo - now that is nice to see. I typed the URL above of the virus that tried to hump my PC on that day. And now I see the domain name gets blocked. I think this is the same virus that got the BBC website ( http://www.theregister.co.uk/2011/02...veby_download/ ) From that nice place the cocos islands. If the BBC, with its huge site and cash investments gets nailed, then I think Winamp Admins can be forgiven. ![]() |
![]() |
![]() |
![]() |
#24 |
Junior Member
|
Your nothing more than a Troll jaromanda.
|
![]() |
![]() |
![]() |
#25 |
Junior Member
Join Date: Apr 2007
Posts: 12
|
Must.. not.. feed.. the.. troll..
I have used Winamp for more years than I care to remember. Just because I haven't posted much doesn't mean that I don't know what I am talking about. *expletive deleted* happens - I understand that. I just want clarification as to what was lost so I can assess the potential damage. I don't want some nobody from Deservesakicking, Illinois telling me what I should think. Edit: I just looked over my very small posting history and saw one of my original posts that I joined the forum to create. It was a step by step guide to show people how to get shoutcast running as a Windows service. Speak little, but when you do make sure the message is useful. Maybe you should try that. |
![]() |
![]() |
![]() |
#26 | ||
Junior Member
|
Quote:
Quote:
|
||
![]() |
![]() |
![]() |
#27 | |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
Quote:
1) email address, stolen 2) suggest you change password 3) change password on other sites if same as here all other possible stolen info is already public in your profile ... so it's not really stolen, is it from 1) you MAY get spam ... I'm sure you do already from 2) you change your password, no big deal from 3) if applicable, you learn not to use the same password on different sites not sure what else you want? class action lawsuit? "If you don't like DNAS, write your own damn system" So I did |
|
![]() |
![]() |
![]() |
#28 | ||
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
Quote:
Please, Mr 4 posts, don't think you can tell me what to do on this forum ... I'll take direction from admin/moderators ... but not from Chicken "the sky is falling" Little Quote:
all other info possibly "stolen" was clearly visible in your public profile here ... so ... you going to sue AOL for leaking information you gave out willingly and publicly? read my sig .... and take into consideration I'm also modest "If you don't like DNAS, write your own damn system" So I did |
||
![]() |
![]() |
![]() |
#29 |
Junior Member
Join Date: Apr 2007
Posts: 12
|
Information in your profile could include your web address.
A whois search could then reveal your real name *edit* and address. Not Winamp's fault but a link in a chain. The date of birth could be stored in the forum database so they can send you birthday greetings. It doesn't have to appear on your profile page ("Hide age and date of birth"). Now I potentially have a name, address, email and a date of birth. A little social engineering and I can get access to your ICQ account. Then I can take over the world. Or something. It's been done before. Just not by me. |
![]() |
![]() |
![]() |
#30 | ||
Junior Member
|
Quote:
Quote:
|
||
![]() |
![]() |
![]() |
#31 | |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
Quote:
see a little humour never hurt "If you don't like DNAS, write your own damn system" So I did |
|
![]() |
![]() |
![]() |
#32 | ||
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
Quote:
so why were you told to change them? Quote:
![]() - or - I know a lot more about this forum than johnny come seldoms code: sorry, I said encrypted ... but 99% of n00bs wouldn't understand "hashed" "If you don't like DNAS, write your own damn system" So I did |
||
![]() |
![]() |
![]() |
#33 |
Junior Member
|
Waste of effort conversing with you as there seems some kind of language barrier, as you continually misinterpret plain English, which as Troll seems to be your primary language is probably not surprising.
|
![]() |
![]() |
![]() |
#34 | |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
and yet, here you are
Quote:
I never claimed you told me to STFU ... I was not rude or disrespectful to you until you basically told me to stop posting not ONE admin/mod has corrected any points in any of my posts why do you think that is? because it's COMMON SENSE "If you don't like DNAS, write your own damn system" So I did |
|
![]() |
![]() |
![]() |
#35 |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
http://forums.shoutcast.com/online.p...members&pp=200
ROFL look at all the users in the control panel hardly any are bitchin an moanin in this thread "If you don't like DNAS, write your own damn system" So I did |
![]() |
![]() |
![]() |
#36 | |
Junior Member
Join Date: Apr 2007
Posts: 12
|
Quote:
|
|
![]() |
![]() |
![]() |
#37 |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
yeah, because it takes HOURS to do that
![]() "If you don't like DNAS, write your own damn system" So I did |
![]() |
![]() |
![]() |
#38 |
Major Dude
Join Date: Jan 2006
Location: Cananada
Posts: 841
|
As I understand it, the MD5 hashes which *MAY* have also been taken in addition to the emails (as written in the security bulletin), could be used to generate a collision (ie. something which has the same hash) and that could be used to login to your Winamp Forums account.
The odds of the collision being your actual password are minimal so your password will most likely be safe on other sites unless they also use MD5 hashes, but to err on the side of caution we've all been advised to change passwords on other sites if it's the same. At the very (very) least your Winamp forum password should be changed. Hope that helps anyone who's still a bit confused. Request: A little SmartView Query Language love. |
![]() |
![]() |
![]() |
#39 |
Junior Member
Join Date: Apr 2007
Posts: 12
|
MD5 Rainbow tables.
Ask google about them. Says it all really. |
![]() |
![]() |
![]() |
#40 |
Forum King
Join Date: Jun 2007
Location: Under the bridge
Posts: 2,290
|
I'll take "Common Sense on the Internet" for 400, please, Alex
"If you don't like DNAS, write your own damn system" So I did |
![]() |
![]() |
![]() |
|
Tags |
angry, breach, security, winamp |
Thread Tools | Search this Thread |
Display Modes | |
|
|